The latest in AI, every dayAI News

Code · August 20, 2026

An honest security check for your function, no jargon

Paste a function that handles user data and get an honest check of common risks (unvalidated input, exposed data, loose permissions), explained without jargon.

You don't need to be a security engineer to know if your code has an obvious hole. This prompt reviews your function the way a senior would before a deploy: what the risk is, how it would be exploited, and the fix ready to go, no jargon you don't understand.

For: ClaudeChatGPTClaude Code
Full prompt
Act as a senior security engineer reviewing production code before it ships, with an eye for
the common mistakes that cause real breaches (not theoretical lab vulnerabilities), and who
explains everything in plain language for someone who doesn't live and breathe infosec.

I'm going to paste a function (or block of code) that handles user data. Your job is to review
it as if it were shipping to production tomorrow.

Language or framework: [E.G. JavaScript/Node, Python/Django, PHP]
What this function does: [E.G. handles the signup form, saves a payment, looks up a user by ID]
Where the data it receives comes from: [E.G. a public form, an API endpoint, a file uploaded by the user]
The code: [PASTE THE FULL FUNCTION HERE]

Check specifically for:
1. Unvalidated or unsanitized input (what happens if someone sends something weird, empty,
   huge, or with code inside it?).
2. Exposed sensitive data (passwords, tokens, payment or personal data that gets stored, logged,
   or returned without needing to be).
3. Permissions and access control (can a user see or modify data that isn't theirs?).
4. Injection (SQL, command, HTML/script) if it applies to the language or database I'm using.
5. Error handling that leaks more than it should (error messages with internal details, stack
   traces shown to the user).

For each risk you find, give me:
- What the risk is, in plain language (without assuming I know security terminology).
- A concrete example of how someone would exploit it with this specific code.
- How severe it is (critical, medium, low) and why.
- The fix, with the corrected code ready to copy.

At the end, if any part of the code you reviewed is clean, tell me that too (don't invent
problems that aren't there).

Anti-hallucination rules: don't assume external libraries, validations, or protections that
aren't in the code I gave you. If you need to know something about the rest of the system
(e.g. whether there's already an auth middleware) to give an accurate verdict, mark it as
[needs verification] instead of assuming it exists.
Short link: wandabuilds.ai/p/83Jj

Come back tomorrow for another, or see all prompts.